AI Agents Expose Long-Standing OAuth Token Security Gaps in Enterprise Tools
Recent breaches at Vercel and Composio involved no phishing — attackers simply stole pre-approved OAuth tokens, bypassing users entirely. OAuth token abuse has been a known vulnerability in platforms like Google Workspace and Microsoft 365 for years, but AI agents have widened the risk by acting autonomously with overly broad, long-lived permissions. Unlike compromised passwords, stolen tokens can grant access across multiple connected services simultaneously, increasing the potential damage. The core challenge for security teams is that AI agents lack human behavioral patterns, making existing anomaly-detection tools unreliable for spotting misuse. Experts urge developers to treat OAuth scope selection as a security decision and call on security teams to audit agent identities and enforce least-privilege access more rigorously.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in